Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Judi Lynn

(160,542 posts)
Wed Aug 20, 2014, 06:21 PM Aug 2014

'Machete' espionage campaign targets orgs in Venezuela, Ecuador

August 20, 2014
'Machete' espionage campaign targets orgs in Venezuela, Ecuador

An attack campaign, dubbed “Machete,” has primarily targeted Spanish speaking victims in Venezuela, Ecuador and Colombia, security firm Kaspersky revealed.

In a Wednesday blog post, researchers said they discovered the threat when a client found unknown malware on their machine after a trip. Kaspersky eventually found that the malware (detected as Trojan-Spy.Python.Ragua.) was being used to further cyber espionage attacks through keystroke logging, audio and screenshot capturing, file stealing and other surveillance capabilities.

The campaign, which dates back to 2010, was “renewed with an improved infrastructure in 2012,” Kaspersky revealed, as may still be active. The threat has been spread via drive-by download and spear phishing emails containing PowerPoint presentation attachments.

Attackers targeted high-profile organizations, such as intelligence services, government institutions and military in Venezuela, Ecuador, Colombia, Peru, Cuba, Spain and Russia (where an embassy for one of the named countries was targeted).

http://www.scmagazine.com/machete-espionage-campaign-targets-orgs-in-venezuela-ecuador/article/367252/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SCMagazineNews+%28SC+Magazine+News%29

(Short article, no more at link.)

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
'Machete' espionage campaign targets orgs in Venezuela, Ecuador (Original Post) Judi Lynn Aug 2014 OP
The targets are intelligence services, gov't institutions and military in these countries. Peace Patriot Aug 2014 #1
More: "Denounce espionage campaign against Latin America" Judi Lynn Aug 2014 #2

Peace Patriot

(24,010 posts)
1. The targets are intelligence services, gov't institutions and military in these countries.
Fri Aug 22, 2014, 02:43 AM
Aug 2014

The title is a little misleading. I understood "orgs" (in the title) to mean NGOs, non-profits, human rights groups, community organizations, etc.--until I read the article to the end.

We need to know more about "Machete"--who's behind it, what their purposes are.

Thanks for posting!

Judi Lynn

(160,542 posts)
2. More: "Denounce espionage campaign against Latin America"
Sun Aug 24, 2014, 02:03 AM
Aug 2014

Denounce espionage campaign against Latin America
19 agosto, 2014

A campaign of cyber espionage to encode military, diplomatic and governmental information is underway in Latin America since 2010, and has exposed countries like Colombia, Ecuador and Venezuela, Russian investigators say.

“We can not speculate on the origins, but we know who is behind speaking Spanish and Latin American. Were stolen hundreds of gigabytes of classified information,” said the director in Latin America of the Russian firm Kaspersky Lab, Dmitry Bestuzhev in Cartagena (northern Colombia).

The campaign called “Machete” the Russians were able to find a package of Java software, folders libraries for recording audio files, encrypted files and programming languages. The program also allowed physical search for victims and steal information using a special USB.

Dimitry spoke about this controversial topic at the Summit of Security Analysts, “The hyper and its implications for privacy and security” organized Russian firm business in Cartagena.

Stresses that of all people affected by espionage, 46 percent are in Venezuela, 36 percent in Ecuador and 11 percent in Colombia, said the Russian officer.

“The attackers were not interested in money, but in highly classified information of military, military deployment, payroll, radar, all you have to do with the national security of a government,” said Dimitry.

http://lainfo.es/en/2014/08/19/denounce-espionage-campaign-against-latin-america/

[center]~ ~ ~[/center]
Kaspersky Lab identifies a cyber-espionage campaign targeting Latin America
20 Aug 2014
Virus News

Kaspersky Lab announces the discovery of a new cyber-espionage campaign code-named ‘Machete’. This campaign has been targeting high profile victims, including government, military, law enforcement agencies and embassies for at least four years. The primary field of operation is Latin America: most of the victims appear to be located in Venezuela, Ecuador and Colombia; other affected countries include Russia, Peru, Cuba, and Spain. The objective of the attackers is to hijack sensitive information from the compromised organizations – so far this threat actor has managed to successfully steal gigabytes of confidential data.

“Despite the simplicity of the tools used in this campaign, the results show it was very effective. It looks like threat actors in Latin America are adopting techniques of APT campaigns seen around the world. We expect local cyber-espionage campaigns to reach increased levels of technological sophistication, and it is likely that new APT campaigns will be similar, from a technical point of view, to the top players worldwide. The best advice here is to think about security globally and stop thinking Latin American countries are free of those threats”, said Dmitry Bestuzhev, Head of Kaspersky Lab’s Global Research and Analysis Team, Latin America.

All indications are that the Machete started in 2010 and was updated with renewed infrastructure in 2012. The attackers used social engineering techniques to distribute the malware. In some cases, they used spear-phishing messages combined with web-based infections spread through specially-prepared fake blogs. At the moment, there are no indications of exploits using zero-day vulnerabilities. All the technical artifacts found in this campaign (like cyber-espionage tools and client side code) have rather low technical sophistication in comparison with other targeted campaigns. Despite this simplicity, Kaspersky Lab experts identified 778 victims around the globe.

Based on the evidence uncovered during Kaspersky Lab’s investigation, experts concluded that the attackers of the campaign appear to be Spanish speaking, and have roots somewhere in Latin America. Also, the targets were mostly Latin America countries. When targets outside of the region were found, there was sometimes a link to Latin America. For instance, in Russia the target appeared to be the embassy of one of the Latin America countries.

More:
http://www.kaspersky.com/about/news/virus/2014/Kaspersky-Lab-identifies-cyber-espionage-campaign-targeting-Latin-America

Latest Discussions»Region Forums»Latin America»'Machete' espionage campa...